CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,529 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
36,454 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-22224 KEV | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with l… | Patch first | 9.3 critical | 1.6% | 2025-03-04 |
| CVE-2026-72529 KEV | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, a… | Patch first | 9.8 critical | 1.5% | 2026-08-19 |
| CVE-2026-48027 KEV | Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed… | Patch first | 9.8 critical | 1.3% | 2026-05-27 |
| CVE-2026-65400 KEV | An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma… | Patch first | 9.8 critical | 1.2% | 2026-08-06 |
| CVE-2025-59374 KEV | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supp… | Patch first | 9.8 critical | 1.2% | 2025-12-17 |
| CVE-2026-45321 KEV | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The… | Patch first | 9.6 critical | 1.1% | 2026-05-12 |
| CVE-2026-48172 KEV | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best… | Patch first | 9.8 critical | 1% | 2026-05-21 |
| CVE-2026-8452 KEV | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the applianc… | Patch first | 9.8 critical | 1% | 2026-06-30 |
| CVE-2026-16812 KEV | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and… | Patch first | 10.0 critical | 1% | 2026-07-27 |
| CVE-2026-85102 KEV | Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to e… | Patch first | 9.8 critical | 1% | 2026-09-09 |
| CVE-2026-8398 KEV | A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distribu… | Patch first | 9.8 critical | 1% | 2026-05-15 |
| CVE-2026-84869 KEV | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host… | Patch first | 9.9 critical | 0.9% | 2026-09-08 |
| CVE-2026-93952 KEV | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and… | Patch first | 10.0 critical | 0.9% | 2026-09-22 |
| CVE-2026-46817 KEV | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2… | Patch first | 9.8 critical | 0.8% | 2026-05-28 |
| CVE-2026-5430 KEV | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to… | Patch first | 10.0 critical | 0.6% | 2026-08-06 |
| CVE-2022-42889 EXP | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolati… | Patch early | 9.8 critical | 99.9% | 2022-10-13 |
| CVE-2017-12635 EXP | Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.… | Patch early | 9.8 critical | 99.8% | 2017-11-14 |
| CVE-2017-8917 EXP | SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors. | Patch early | 9.8 critical | 99.8% | 2017-05-17 |
| CVE-2020-10220 EXP | An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter. | Patch early | 9.8 critical | 99.7% | 2020-03-07 |
| CVE-2023-27372 EXP | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,… | Patch early | 9.8 critical | 99.7% | 2023-02-28 |
| CVE-2022-37061 EXP | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject an… | Patch early | 9.8 critical | 99.6% | 2022-08-18 |
| CVE-2023-32560 EXP | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code executi… | Patch early | 9.8 critical | 99.4% | 2023-08-10 |
| CVE-2025-1974 EXP | A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve a… | Patch early | 9.8 critical | 99.4% | 2025-03-25 |
| CVE-2017-12542 EXP | A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found. | Patch early | 10.0 critical | 99.3% | 2018-02-15 |
| CVE-2023-23333 EXP | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions throug… | Patch early | 9.8 critical | 99.3% | 2023-02-06 |
| CVE-2025-29927 EXP | Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 1… | Patch early | 9.1 critical | 99.2% | 2025-03-21 |
| CVE-2022-24637 EXP | Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin… | Patch early | 9.8 critical | 99.1% | 2022-03-18 |
| CVE-2020-7209 EXP | LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2. | Patch early | 9.8 critical | 98.8% | 2020-02-13 |
| CVE-2018-19276 EXP | OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary command… | Patch early | 9.8 critical | 98.7% | 2019-03-21 |
| CVE-2020-15920 EXP | There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (… | Patch early | 9.8 critical | 98.2% | 2020-07-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt